First published: Tue Dec 15 2020(Updated: )
By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab while the URL bar displayed the original domain. *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <84 | 84 |
Firefox | <84.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-26977 is classified as a medium severity vulnerability affecting Firefox for Android.
To mitigate CVE-2020-26977, you should upgrade to Mozilla Firefox version 84 or later.
Yes, CVE-2020-26977 only affects Firefox for Android and does not impact other operating systems.
Exploiting CVE-2020-26977 could allow an attacker to control the content of a tab while misleading users about the domain displayed in the URL bar.
CVE-2020-26977 affects all versions of Firefox prior to version 84.